PSIRT

Mitsubishi Electric India

Product Security Incident Response Team

Basic policy

Mitsubishi Electric India is committed to ensuring the highest standards of security across all its products and services. To strengthen this commitment, the company has established PSIRT (Product Security Incident Response Team) as an internal framework for responding to the incidents related to the information security of our products and services.

The PSIRT will be responsible for:

  • Collecting and analyzing information related to potential vulnerabilities in products and services.
  • Coordinating swift and effective countermeasures in collaboration with product design, manufacturing, and customer support departments.
  • Transparently disclosing relevant vulnerability information and remediation measures to customers.

Mitsubishi Electric India actively promotes secure product design and development practices aimed at preventing vulnerabilities before products and services reach the customers. As part of this initiative:

  • Secure development methodologies are integrated into all stages of product development.
  • Comprehensive Product Security Training is conducted for all the executives and employees involved in product development and support.

Legal Compliance

We will comply with all relevant laws and regulations related to Product Security. In addition, we will take appropriate measures to protect personal information.

Vulnerability disclosure policy

Reporting

To enhance the security of our products, we actively receive and assess vulnerability information from external security researchers and established coordinating organizations, including national CERTs. Suspected vulnerabilities in our products can be reported directly to us through the vulnerability reporting form.

Investigation and countermeasures

The relevant product design and development department will review and investigate the vulnerability information provided by the reporter. If the defined evaluation criteria are met, the issue will be classified as a confirmed vulnerability, and the results of the investigation will be communicated to the reporter. Additional information may be requested as necessary during the investigation.

We will implement countermeasures and prepare to disclose a new vulnerability.

Publication of security advisory

To enable customers to take appropriate measures against identified vulnerabilities, a security advisory will be prepared and published. The publication date will be coordinated with the reporter and other relevant stakeholders once the advisory is ready for release. Following the assignment of a CVE identifier, the advisory will be published on our website.

At the same time, the vulnerability will be communicated to the NCERT and to the CERT of each country, as necessary.

Vulnerability advisory

Refer to the list below for current vulnerability disclosures. Disclosures are organized by year.

Date YYYY/MM/DD Product Category Pdf File Vulnerability Disclosure Description
Page 1 of 1

Vulnerability report form

Please provide the following information (in English) and read the personal information disclosure statement at the bottom of the page.
If you agree with the statement, please click the "Agree & Proceed" button.
* indicates a required field

Letters and spaces only. Name is required (max 50 characters).
Letters, spaces, and . , & - only (max 100 characters).
Invalid phone number. Enter 10 digits or start with +91 (e.g. 9876543210 or +91 9876543210).
Please enter a valid e-mail address (max 100 characters).
Product name is required (max 100 characters).
Vulnerability details are required (max 2000 characters).

How we handle your personal information

Please be sure to read this before contacting us, and if you agree, please check "Agree & Proceed" and proceed to the confirmation screen.
This agreement is at your discretion. However, if you do not agree, we will not be able to accept a vulnerability report.

Handling your personal information:

We take the utmost care in responsibly managing the personal information we receive from you (your name, e-mail address, telephone number, etc.) when you send in a vulnerability report via the Mitsubishi Electric web site.

Mitsubishi Electric India will use the personal information we receive from you to respond to and confirm the report you send to us, and may keep a record of the report for the same purposes.

To provide an appropriate response to your report, we may at times forward your report, along with your personal information, to our subsidiaries or subcontractors (such as distributors).

Mitsubishi Electric India will not disclose your personal information to a third party for purposes other than that mentioned above.

If you are under the age of 16, we ask that you consult with your parent(s) or guardian(s) before registering your personal information.

Submitting your report indicates your understanding of and agreement with the above terms and conditions.

Enter Verification Code

We have sent a 6-digit verification code to user@example.com.
Please enter the code below to verify your email and complete the submission.

Resend code in 60 seconds

Report Submitted Successfully

Thanks for your expertise and sincere efforts in identifying and reporting security issues in Mitsubishi Electric India products. We will be in touch with you soon and would like to work with you to mitigate the issues at earliest.